Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

55255
Total
4360
Critical
16420
High
16093
Medium
CVE ID Severity Score Description Published
CVE-2026-65121 HIGH 8.2 NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an improper authentication issue. A successful exploit of this vulnerability might lead … Sep 22, 2026
CVE-2026-65118 HIGH 7.5 NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to … Sep 22, 2026
CVE-2026-65117 MEDIUM 5.0 NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of a hard-coded password. A successful exploit of this vulnerability might … Sep 22, 2026
CVE-2026-65115 MEDIUM 6.5 NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker may cause uncontrolled resource consumption. A successful exploit of this vulnerability may lead to … Sep 22, 2026
CVE-2026-65114 HIGH 8.3 NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function. A successful exploit of this vulnerability … Sep 22, 2026
CVE-2026-65113 CRITICAL 9.8 NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of hard-coded credentials. A successful exploit of this vulnerability might lead … Sep 22, 2026
CVE-2026-65112 MEDIUM 6.5 NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to … Sep 22, 2026
CVE-2026-65111 HIGH 7.8 NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious input created by an attacker could cause a code injection. A successful exploit of … Sep 22, 2026
CVE-2026-24267 HIGH 7.8 NVIDIA NeMo Speech for all platforms contains a vulnerability in the speech data explorer component, where malicious data created by an attacker could cause remote … Sep 22, 2026
CVE-2026-24239 HIGH 7.8 NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious data created by an attacker could cause remote code execution. A successful exploit of … Sep 22, 2026
CVE-2026-19915 UNKNOWN — A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.55.10.0. The vulnerability could potentially allow a local attacker … Sep 22, 2026
CVE-2026-95682 UNKNOWN — MISP contains a stored cross-site scripting (XSS) vulnerability in the admin email composition screen. The MISP.org organization name setting was interpolated directly into a JavaScript … Sep 22, 2026
CVE-2026-95679 UNKNOWN — MISP's RequestHandlerComponent automatically decodes XML request bodies on all write requests. The underlying Xml::build() library contains a logic error in its readFile guard condition (readFile … Sep 22, 2026
CVE-2026-95675 CRITICAL 9.8 D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary commands as root by … Sep 22, 2026
CVE-2026-95674 UNKNOWN — In MISP, the queryEnrichment method in EventsController.php accepted a module name parameter and iterated over the list of enabled modules to find a match. If … Sep 22, 2026
CVE-2026-95671 UNKNOWN — In MISP, the CollectionsController add() method enforced the sharing-group usability authorization check and element capture only when the HTTP request method was POST. However, the … Sep 22, 2026
CVE-2026-95667 UNKNOWN — The MISP installer scripts (for Debian 12, Debian 13, Ubuntu 24.04, and RHEL 9.4) create a log file at /var/log/misp_install.log and a named pipe (FIFO) … Sep 22, 2026
CVE-2026-95666 MEDIUM 4.3 Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to limit the length of the post ID array accepted … Sep 22, 2026
CVE-2026-95665 UNKNOWN — MISP contains a reflected cross-site scripting (XSS) vulnerability in the event REST search export confirmation form. The view template app/View/Events/ajax/eventRestSearchExportConfirmationForm.ctp renders a URL-supplied event ID … Sep 22, 2026
CVE-2026-95499 HIGH 7.3 A flaw has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. This issue affects the function move_uploaded_file of the file filemanager.php. Executing a manipulation of … Sep 22, 2026
CVE-2026-95396 MEDIUM 4.3 A vulnerability was identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. Affected is an unknown function of the file HospitalController.java of the component Public Search Handlers. … Sep 22, 2026
CVE-2026-93343 MEDIUM 6.5 MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_admin_vendors_ajax AJAX action that allows authenticated attackers with subscriber-level access or higher … Sep 22, 2026
CVE-2026-93342 MEDIUM 5.4 MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_duplicate_product AJAX action that allows authenticated attackers with subscriber-level access or higher … Sep 22, 2026
CVE-2026-93341 MEDIUM 4.3 MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_send_refund AJAX action that allows authenticated attackers with subscriber-level access or higher … Sep 22, 2026
CVE-2026-12718 CRITICAL 9.8 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Karel Electronic Industry and Trade Inc. KarelIPS allows Blind SQL Injection. … Sep 22, 2026